Two questions about syslog-ng

Mik J <[email protected]> Thu, 8 Dec 2022 00:50:37 +0000 (UTC)
Newsgroups gmane.comp.syslog-ng
Message-ID <[email protected]>
Hello,

I would like to know if syslog-ng is able to collect netflow and/or sflow flows.
Logstash used to do it through the netflow module.

Is it possible to start a script when receiving a specific syslog ?

Log received
DecĀ  7 22:36:10 myserver sshd[46926]: somemessage from 192.168.2.201 port 59489 ssh2
Action
/somewhere/script_ban_ip 192.168.2.201

Thank you
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq